cxf-rt-transports-jms is vulnerable to Improper Input Validation
81
High Risk
A further incomplete fix for CVE-2026-44417 leaves additional JNDI validation gaps in Apache CXF JMS configuration handling. If untrusted users can supply JMS or JNDI settings, attacker-controlled environment properties or URL-style JNDI names can still reach unsafe lookup paths and may lead to remote code execution.
You are affected if you are using a version that falls within the vulnerable range and if untrusted users are allowed to configure JMS for Apache CXF.
cxf-rt-transports-jms is vulnerable to Improper Input Validation in versions 0.0.0 - 4.1.6 and 4.2.0 - 4.2.1.
Upgrade the org.apache.cxf:cxf-rt-transports-jms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant